regbor Публикувано Септември 3, 2009 Report Share Публикувано Септември 3, 2009 Наскоро попаднах на един лаптоп, изоставен отвсякъде ... без защитна стена,без антивирусна защита и т.н. По принцип функционира нормално, като изключим около 200-тате троянеца , които махнах чрез Spybot S&D (единственото което успях да кача)... Всеки друг опит да кача някакъв антивирусен продукт беше неуспешен... Още докато набирам страницата или препратката към някаква антивирусна и цялата сесия се затваря сама, остава само десктопа. Не ми позволи да сваля и Hi Jack-а поне да видя за какво става въпрос...Някой има ли идея каква е причината? Цитирай Link to comment Сподели другаде More sharing options...
draco_volans Публикувано Септември 4, 2009 Report Share Публикувано Септември 4, 2009 Според мен причината са гадинки, които като усетят че набираш адреса на антивирус и веднага ти хлопват вратата... Може rootkit-че да има... Щом S&D толкова много е махнал, колко ли гадинки са останали... Пробвай да дръпнеш антивирусна не от официален сайт... Например тракер (не задължително да е пиратска)... Можеш да потърсиш Malwarebyte's Antimalware и SuperAntispyware Free от такива места и да направиш сканиране с тях... Предполагам, някой по-голям разбирач също ще вземе отношение по въпроса... Можеш да изтеглиш нужните програми и от друг компютър да ги запишеш на диск (не на флашка!) и да ги инсталираш от него. Към тези програми можеш да включиш и GMER (правиш бързо сканиране с него, отказваш пълното сканиране), ESETSysInspector (съхраняваш лога без да го разархивираш). Можеш да качиш логовете тук (от сканираниятя с антивирусните и с по горните програмки), включително и от сканирането с HiJackThis (преименувай екзето на програмата на друго име, преди да я стартираш). Цитирай Link to comment Сподели другаде More sharing options...
crazyfrog Публикувано Септември 4, 2009 Report Share Публикувано Септември 4, 2009 Аз бих преинсталирал. Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Септември 4, 2009 Report Share Публикувано Септември 4, 2009 Един лог от ESET SysInspector може да е от помощ:1) стартирай я, скролирай до долу и кликни I Agree, след което изчакай да събере информацията;2) меню File -> Save Log;3) потвърди с Yes;4) не променяй изходния ZIP формат, запази файла на удобно за теб място и го прикачи после към коментара си (не го разархивирай). Изтегли GMER. Разархивирай и стартирай програмата. Тя ще направи начално сканиране за секунди. След като то приключи НЕ кликай бутон Scan, а кликни бутон Copy и после пейстни съдържанието тук (Ctrl+V). Ако програмата предложи да направи пълно сканиране, откажи. Сваляй от нашите миръри, ако не е достъпно да сваляш от официалните линкове. Цитирай Link to comment Сподели другаде More sharing options...
regbor Публикувано Септември 4, 2009 Author Report Share Публикувано Септември 4, 2009 Пропуснах да добавя, че SysInspectora na NOD също не може да се качи, а така също и антивирусни от други източници...простостраницата се затваря! Успях да сканирам с онлайн скенера на ЕСЕТ,но зА мое голямо учудване не откри нищо... А проблема с качването на антивирусна остава... Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Септември 4, 2009 Report Share Публикувано Септември 4, 2009 Как така не иска да се качи? Опита ли да свалиш програмата от сайта, който ти дадох и от миръра на Superhosting? Цитирай Link to comment Сподели другаде More sharing options...
regbor Публикувано Септември 5, 2009 Author Report Share Публикувано Септември 5, 2009 Опитах, но без успех. В момента в който започне да зарежда за да сваля, процеса на сваляне спира... Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Септември 5, 2009 Report Share Публикувано Септември 5, 2009 Пробвай да изтеглиш този файл (ComboFix), който съм преименувал нарочно на sVchost.exe , но НЕ ГО СТАРТИРАЙ все още. Запaзи го на Десктопа и от START => RUN въведи следната команда: "%userprofile%\desktop\sVchost.exe" /stepdel Копирай лог файла, който програмата ще създаде след рестарта на машината. Цитирай Link to comment Сподели другаде More sharing options...
regbor Публикувано Септември 5, 2009 Author Report Share Публикувано Септември 5, 2009 ComboFix 09-09-04.02 - Petia 05.09.2009 17:04.1.1 - FAT32x86Microsoft Windows XP Home Edition 5.1.2600.2.1251.359.1033.18.502.174 [GMT 3:00]Running from: c:\documents and settings\Petia\Desktop\ComboFix.exeCommand switches used :: /stepdel WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))). c:\program files\WinPCapc:\program files\WinPCap\daemon_mgm.exec:\program files\WinPCap\npf_mgm.exec:\program files\WinPCap\rpcapd.exec:\windows\Installer\WMEncoder.msic:\windows\system32\bootvidl.exec:\windows\system32\drivers\npf.sysc:\windows\system32\Packet.dllc:\windows\system32\pthreadVC.dllc:\windows\system32\WanPacket.dllc:\windows\system32\wpcap.dllc:\documents and settings\Petia\Application Data\wiaserva.logc:\windows\rasqervy.dllc:\windows\sdfinacs.dllc:\windows\sdfixwcs.dllc:\windows\system32\2646507927.datc:\windows\system32\drivers\d0162d80.sys . . . . failed to deletec:\windows\system32\kdpini.dllc:\windows\wuasirvy.dllD:\Autorun.inf .((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))). -------\Legacy_NPF-------\Legacy_termservicenmsaccessu-------\Service_NPF-------\Service_TermServiceNMSAccessU-------\Service_d0162d80 ((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 ))))))))))))))))))))))))))))))). 2009-08-28 23:40 . 2009-08-28 23:40 39936 ----a-w- c:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sys2009-08-25 18:35 . 2009-08-25 18:35 -------- d-----w- c:\windows\system32\NtmsData2009-08-24 21:01 . 2009-08-24 21:02 -------- d-----w- c:\program files\Spybot - Search & Destroy2009-08-23 19:46 . 2009-08-23 19:47 -------- d-----w- c:\temp\Fracture.2007.DVDRip.XViD.AC3.iNT-CiMG2009-08-22 00:45 . 2009-08-22 00:45 -------- d-----w- c:\temp\Ice Age 3 - Dawn Of The Dinosaurs (2009) - R5.LiNE.Subs (In Sync) - FUSiON .(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-09-05 14:11 . 2009-05-31 09:12 99776 ----a-w- c:\windows\system32\drivers\d0162d80.sys2009-09-05 14:09 . 2008-01-27 06:01 12 ----a-w- c:\windows\bthservsdp.dat2009-05-23 07:05 . 2009-04-17 11:48 67088 ----a-w- c:\program files\mozilla firefox\components\bcbfcaafdbaeb.dll. ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-10 212992]"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-9-19 581693] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bfbafeffaecaf]2006-05-08 04:14 280079 ----a-w- c:\windows\system32\bfbafeffaecaf.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"wave1"=c_693237.nls"midi1"=c_693237.nls"mixer1"=c_693237.nls"wave2"=c_693237.nls"midi2"=c_693237.nls"mixer2"=c_693237.nls"aux2"=c_693237.nls"aux1"=c_693237.nls [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnkbackup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]"WMPNetworkSvc"=3 (0x3)"usnjsvc"=3 (0x3)"gusvc"=3 (0x3)"AWService"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center]"UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"c:\\WINDOWS\\system32\\sessmgr.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="c:\\Program Files\\FlashGet\\flashget.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]"AllowInboundEchoRequest"= 1 (0x1)"AllowInboundTimestampRequest"= 1 (0x1)"AllowInboundMaskRequest"= 1 (0x1)"AllowInboundRouterRequest"= 1 (0x1)"AllowOutboundDestinationUnreachable"= 1 (0x1)"AllowOutboundSourceQuench"= 1 (0x1)"AllowOutboundParameterProblem"= 1 (0x1)"AllowOutboundTimeExceeded"= 1 (0x1)"AllowRedirect"= 1 (0x1)"AllowOutboundPacketTooBig"= 1 (0x1) R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [04.08.2004 5:00 14336]S0 237d3e837cccc498941ec8b2180b3da2;237d3e837cccc498941ec8b2180b3da2;c:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sys [29.08.2009 2:40 39936]S3 UnlockerDriver4;UnlockerDriver4 Driver;c:\program files\Unlocker\UnlockerDriver4.sys [25.07.2005 6:31 3584]..------- Supplementary Scan -------.IE: &Сваляне на всички с FlashGet - c:\progra~1\FlashGet\jc_all.htmIE: &Сваляне с FlashGet - c:\progra~1\FlashGet\jc_link.htmIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000TCP: {0287E462-2975-49A3-A896-3A1BF3BC82DF} = 10.28.4.1FF - ProfilePath - c:\documents and settings\Petia\Application Data\Mozilla\Firefox\Profiles\nbt5h1zi.default\FF - component: c:\program files\Mozilla Firefox\components\bcbfcaafdbaeb.dll. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-09-05 17:11Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d0162d80]"ImagePath"="\SystemRoot\System32\drivers\d0162d80.sys".--------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\elevation]"Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\localserver32]@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\typelib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}]@Denied: (A 2) (Everyone)@="IFlashBroker3" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}\proxystubclsid32]@="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}\typelib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".--------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(924)c:\windows\system32\bfbafeffaecaf.dll - - - - - - - > 'explorer.exe'(3160)c:\windows\system32\WPDShServiceObj.dllc:\windows\system32\btncopy.dllc:\windows\system32\PortableDeviceTypes.dllc:\windows\system32\PortableDeviceApi.dll.------------------------ Other Running Processes ------------------------.c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXEc:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXEc:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXEc:\program files\CDBURNERXP\NMSACCESSU.EXEc:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXEc:\windows\SYSTEM32\SNMP.EXEc:\windows\system32\wscntfy.exec:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE.**************************************************************************.Completion time: 2009-09-05 17:13 - machine was rebootedComboFix-quarantined-files.txt 2009-09-05 14:13 Pre-Run: 6 651 346 944 bytes freePost-Run: 6 518 243 328 bytes free 185 --- E O F --- 2009-04-16 21:31 Цитирай Link to comment Сподели другаде More sharing options...
SexyGazar4e Публикувано Септември 5, 2009 Report Share Публикувано Септември 5, 2009 Дай Start -> Run и пиши msconfig , после в таба BOOT.INI виж какво ще ти излезне и го копирай тук. Отиди после на Services , дай тикчето на Hide all Microsoft Services , и пиши пак какво ти излиза ( кой процеси са активни и кой не са ) После отиди в Startup и пиши пак кой са активните процеси и командата..*Пример: Startup tem: Command:VMSnap23.exe C:\Windows\VMSnap23.exe Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Септември 5, 2009 Report Share Публикувано Септември 5, 2009 СТЪПКА 1 Първо спри защитата на Spybot S & D => TeaTimer => Отиди на Mode => премини в Advanced Mode. Сега разгърни Tools => Resident => и премахни отметката пред TeaTimer, но остави тази на SDHelper. http://wiki.pomona.edu/pub/FAQ/TeaTimer/EnableTeaTimer.PNG СТЪПКА 2 Отвори notepad и чрез copy/paste въведи: KILLALL::Driver::237d3e837cccc498941ec8b2180b3da2NwSapAgentRootkit::c:\windows\system32\drivers\d0162d80.sysc:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sysFile::c:\program files\mozilla firefox\components\bcbfcaafdbaeb.dllRegistry::[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bfbafeffaecaf][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"wave1"=-"midi1"=-"mixer1"=-"wave2"=-"midi2"=-"mixer2"=-"aux2"=-"aux1"=-[HKEY_LOCAL_MACHINE\software\microsoft\security center]"UpdatesDisableNotify"=dword:00000000[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d0162d80]Firefox::FF - component: c:\program files\Mozilla Firefox\components\bcbfcaafdbaeb.dllreglock::[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}][HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\elevation][HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\localserver32][HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8e9a-4d4e-9ee9-17a0e48d3bbb}\typelib][HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}][HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}\proxystubclsid32][HKEY_LOCAL_MACHINE\software\Classes\Interface\{1d4c8a81-b7ac-460a-8c23-98713c41d6b3}\typelib] Запази файла с име CFScript и го провлачи чрез drag/drop в ComboFix. http://img522.imageshack.us/img522/482/cfscriptyr1.gif Това ще стартира ComboFix още веднъж. Публикувай лог файла в следващия си пост. Цитирай Link to comment Сподели другаде More sharing options...
regbor Публикувано Септември 5, 2009 Author Report Share Публикувано Септември 5, 2009 ComboFix 09-09-05.02 - Petia 06.09.2009 1:09.2.1 - FAT32x86Microsoft Windows XP Home Edition 5.1.2600.2.1251.359.1033.18.502.224 [GMT 3:00]Running from: c:\documents and settings\Petia\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Petia\Desktop\CFScript.txt WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE ::"c:\program files\mozilla firefox\components\bcbfcaafdbaeb.dll". ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))). c:\program files\Mozilla Firefox\components\bcbfcaafdbaeb.dll .((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))). -------\Legacy_237D3E837CCCC498941EC8B2180B3DA2-------\Legacy_NWSAPAGENT-------\Service_237d3e837cccc498941ec8b2180b3da2-------\Service_NwSapAgent-------\Service_d0162d80 ((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 ))))))))))))))))))))))))))))))). 2009-08-28 23:40 . 2009-09-05 22:13 39936 ----a-w- c:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sys2009-08-25 18:35 . 2009-08-25 18:35 -------- d-----w- c:\windows\system32\NtmsData2009-08-24 21:01 . 2009-08-24 21:02 -------- d-----w- c:\program files\Spybot - Search & Destroy2009-08-23 19:46 . 2009-08-23 19:47 -------- d-----w- c:\temp\Fracture.2007.DVDRip.XViD.AC3.iNT-CiMG2009-08-22 00:45 . 2009-08-22 00:45 -------- d-----w- c:\temp\Ice Age 3 - Dawn Of The Dinosaurs (2009) - R5.LiNE.Subs (In Sync) - FUSiON .(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-09-05 22:13 . 2008-01-27 06:01 12 ----a-w- c:\windows\bthservsdp.dat. ((((((((((((((((((((((((((((( SnapShot@2009-09-05_14.11.47 ))))))))))))))))))))))))))))))))))))))))).+ 2009-09-05 22:15 . 2009-09-05 22:15 16384 c:\windows\temp\Perflib_Perfdata_71c.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-10 212992]"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-9-19 581693] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bfbafeffaecaf]2006-05-08 04:14 280079 ----a-w- c:\windows\system32\bfbafeffaecaf.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnkbackup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]"WMPNetworkSvc"=3 (0x3)"usnjsvc"=3 (0x3)"gusvc"=3 (0x3)"AWService"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"c:\\WINDOWS\\system32\\sessmgr.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="c:\\Program Files\\FlashGet\\flashget.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]"AllowInboundEchoRequest"= 1 (0x1)"AllowInboundTimestampRequest"= 1 (0x1)"AllowInboundMaskRequest"= 1 (0x1)"AllowInboundRouterRequest"= 1 (0x1)"AllowOutboundDestinationUnreachable"= 1 (0x1)"AllowOutboundSourceQuench"= 1 (0x1)"AllowOutboundParameterProblem"= 1 (0x1)"AllowOutboundTimeExceeded"= 1 (0x1)"AllowRedirect"= 1 (0x1)"AllowOutboundPacketTooBig"= 1 (0x1) S3 UnlockerDriver4;UnlockerDriver4 Driver;c:\program files\Unlocker\UnlockerDriver4.sys [25.07.2005 6:31 3584]..------- Supplementary Scan -------.IE: &Сваляне на всички с FlashGet - c:\progra~1\FlashGet\jc_all.htmIE: &Сваляне с FlashGet - c:\progra~1\FlashGet\jc_link.htmIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000TCP: {0287E462-2975-49A3-A896-3A1BF3BC82DF} = 10.28.4.1FF - ProfilePath - c:\documents and settings\Petia\Application Data\Mozilla\Firefox\Profiles\nbt5h1zi.default\. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-09-06 01:15Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0 **************************************************************************.--------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(916)c:\windows\system32\bfbafeffaecaf.dll - - - - - - - > 'explorer.exe'(2104)c:\windows\system32\WPDShServiceObj.dllc:\windows\system32\btncopy.dllc:\windows\system32\PortableDeviceTypes.dllc:\windows\system32\PortableDeviceApi.dll.------------------------ Other Running Processes ------------------------.c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXEc:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXEc:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXEc:\program files\CDBURNERXP\NMSACCESSU.EXEc:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXEc:\windows\SYSTEM32\SNMP.EXEc:\windows\SYSTEM32\WSCNTFY.EXEc:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BTSTACKSERVER.EXE.**************************************************************************.Completion time: 2009-09-05 1:17 - machine was rebootedComboFix-quarantined-files.txt 2009-09-05 22:17ComboFix2.txt 2009-09-05 14:14 Pre-Run: 6 516 408 320 bytes freePost-Run: 6 459 523 072 bytes free 133 --- E O F --- 2009-04-16 21:31 Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Септември 5, 2009 Report Share Публикувано Септември 5, 2009 Отвори notepad и чрез copy/paste въведи: KILLALL::STEPDEL::File::c:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sysc:\windows\system32\bfbafeffaecaf.dllc:\windows\bthservsdp.datRegistry::[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bfbafeffaecaf] Запази файла с име CFScript и го провлачи чрез drag/drop в ComboFix. http://img522.imageshack.us/img522/482/cfscriptyr1.gif Това ще стартира ComboFix още веднъж. Публикувай лог файла в следващия си пост. Накрая архивирай папката C:\Qoobox и я качи на адрес => http://www.4storing.com Благодаря предварително. Цитирай Link to comment Сподели другаде More sharing options...
regbor Публикувано Септември 6, 2009 Author Report Share Публикувано Септември 6, 2009 ComboFix 09-09-05.02 - Petia 06.09.2009 11:56.3.1 - FAT32x86Microsoft Windows XP Home Edition 5.1.2600.2.1251.359.1033.18.502.157 [GMT 3:00]Running from: c:\documents and settings\Petia\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Petia\Desktop\CFScript.txt WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE ::"c:\windows\bthservsdp.dat""c:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sys""c:\windows\system32\bfbafeffaecaf.dll". ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))). c:\windows\bthservsdp.datc:\windows\system32\237d3e837cccc498941ec8b2180b3da2.sysc:\windows\system32\bfbafeffaecaf.dll . . . . failed to delete .((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 ))))))))))))))))))))))))))))))). 2009-08-25 18:35 . 2009-08-25 18:35 -------- d-----w- c:\windows\system32\NtmsData2009-08-24 21:01 . 2009-08-24 21:02 -------- d-----w- c:\program files\Spybot - Search & Destroy2009-08-23 19:46 . 2009-08-23 19:47 -------- d-----w- c:\temp\Fracture.2007.DVDRip.XViD.AC3.iNT-CiMG2009-08-22 00:45 . 2009-08-22 00:45 -------- d-----w- c:\temp\Ice Age 3 - Dawn Of The Dinosaurs (2009) - R5.LiNE.Subs (In Sync) - FUSiON .(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-09-06 09:01 . 2006-05-08 04:14 280079 ----a-w- c:\windows\system32\bfbafeffaecaf.dll2009-09-06 09:01 . 2006-05-08 04:14 280079 ------w- c:\windows\system32\ec797eaf165bd5f53cc5641ac7f1a35e.TMP. ((((((((((((((((((((((((((((( SnapShot@2009-09-05_14.11.47 ))))))))))))))))))))))))))))))))))))))))).+ 2009-09-06 09:02 . 2009-09-06 09:02 16384 c:\windows\temp\Perflib_Perfdata_c4.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-10 212992]"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-9-19 581693] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bfbafeffaecaf]2009-09-06 09:01 280079 ----a-w- c:\windows\system32\bfbafeffaecaf.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnkbackup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]"WMPNetworkSvc"=3 (0x3)"usnjsvc"=3 (0x3)"gusvc"=3 (0x3)"AWService"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"c:\\WINDOWS\\system32\\sessmgr.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="c:\\Program Files\\FlashGet\\flashget.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]"AllowInboundEchoRequest"= 1 (0x1)"AllowInboundTimestampRequest"= 1 (0x1)"AllowInboundMaskRequest"= 1 (0x1)"AllowInboundRouterRequest"= 1 (0x1)"AllowOutboundDestinationUnreachable"= 1 (0x1)"AllowOutboundSourceQuench"= 1 (0x1)"AllowOutboundParameterProblem"= 1 (0x1)"AllowOutboundTimeExceeded"= 1 (0x1)"AllowRedirect"= 1 (0x1)"AllowOutboundPacketTooBig"= 1 (0x1) S3 UnlockerDriver4;UnlockerDriver4 Driver;c:\program files\Unlocker\UnlockerDriver4.sys [25.07.2005 6:31 3584]..------- Supplementary Scan -------.IE: &Сваляне на всички с FlashGet - c:\progra~1\FlashGet\jc_all.htmIE: &Сваляне с FlashGet - c:\progra~1\FlashGet\jc_link.htmIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000TCP: {0287E462-2975-49A3-A896-3A1BF3BC82DF} = 10.28.4.1FF - ProfilePath - c:\documents and settings\Petia\Application Data\Mozilla\Firefox\Profiles\nbt5h1zi.default\. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-09-06 12:02Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0 **************************************************************************.--------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(916)c:\windows\system32\bfbafeffaecaf.dll - - - - - - - > 'explorer.exe'(3328)c:\windows\system32\WPDShServiceObj.dllc:\windows\system32\btncopy.dllc:\windows\system32\PortableDeviceTypes.dllc:\windows\system32\PortableDeviceApi.dll.------------------------ Other Running Processes ------------------------.c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXEc:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXEc:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXEc:\program files\CDBURNERXP\NMSACCESSU.EXEc:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXEc:\windows\SYSTEM32\SNMP.EXEc:\windows\SYSTEM32\WSCNTFY.EXEc:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BTSTACKSERVER.EXE.**************************************************************************.Completion time: 2009-09-06 12:04 - machine was rebootedComboFix-quarantined-files.txt 2009-09-06 09:04ComboFix2.txt 2009-09-05 22:17ComboFix3.txt 2009-09-05 14:14 Pre-Run: 6 475 546 624 bytes freePost-Run: 6 350 438 400 bytes free 133 --- E O F --- 2009-04-16 21:31 Цитирай Link to comment Сподели другаде More sharing options...
B-boy/StyLe/ Публикувано Септември 6, 2009 Report Share Публикувано Септември 6, 2009 Ще те помоля да изтеглиш прикачение файл... Разархивирай го и го стартирай с двукратен клик на мишката. На въпроса избери YES за да влезнат промените в сила. Рестартирай компютъра. Изтегли The Avenger. Разархивирай и стартирай програмата. Потвърди с OK. Копирай следния скрипт, като го маркираш и натиснеш Ctrl+C, след което в The Avenger кликни третия бутон (Paste Script from Clipboard):Files to delete: c:\windows\system32\bfbafeffaecaf.dll c:\windows\system32\ec797eaf165bd5f53cc5641ac7f1a35e.TMP Registry keys to delete: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\bfbafeffaecafКликни Execute, потвърди с Yes и на двата въпроса, което ще рестартира компютъра. След като се стартира отново ще се изведе текстов файл. Копирай съдържанието му тук.sound.zip Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.